# CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack

> Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.

- Published: 2026-09-01T12:55:00.000Z
- Severity: high
- Category: Vulnerabilities
- Tags: Microsoft Exchange Server, Authentication Bypass, Shadowserver, CVE-2026-62911, Mailbox Hijack
- CVEs: CVE-2026-62911
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
- Canonical: https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack

## Key points

- Nearly 22,000 unpatched Microsoft Exchange servers are exposed to potential mailbox hijack attacks.
- Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE) are vulnerable to CVE-2026-62911.
- Immediately apply the August 2026 Patch Tuesday updates to mitigate the authentication bypass flaw.

## Urgent Threat: Thousands of Exchange Servers Exposed to Mailbox Hijack

Nearly 22,000 Microsoft Exchange servers worldwide remain unpatched against a high-severity authentication bypass [vulnerability](/glossary#vulnerability), [CVE-2026-62911](https://nvd.nist.gov/vuln/detail/CVE-2026-62911), that could allow attackers to fully hijack user mailboxes. This flaw, enabling privilege elevation, poses a significant risk to organizations still operating vulnerable versions of Exchange Server exposed to the internet. While in-the-wild exploitation for this specific [CVE](/glossary#cve) has not yet been confirmed, public [exploit](/glossary#exploit) code is reportedly available, significantly increasing the urgency for immediate patching, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/).

### Understanding CVE-2026-62911: Authentication Bypass in Microsoft Exchange Server

Tracked as CVE-2026-62911, this security vulnerability was reported by DEVCORE Research Team's Orange Tsai. It affects **Exchange Server 2016**, **Exchange Server 2019**, and **Exchange Server Subscription Edition (SE)** software. Microsoft describes it as an "Authentication bypass by capture-replay" that permits an authorized attacker to elevate privileges over a network. This means that an attacker, even with basic privileges on the targeted server, could perform low-complexity attacks that initially require user interaction to gain a foothold. Once exploited, the attacker can take over the mailboxes of all Exchange users, allowing them to send emails, read emails, and download attachments. This represents a complete compromise of communication within the affected organization.

Microsoft addressed this flaw during its August 2026 [Patch](/glossary#patch) Tuesday. However, recent warnings from the Netherlands National Cyber Security Centre (NCSC-NL) indicate that exploit code for [CVE-2026-62911](https://nvd.nist.gov/vuln/detail/CVE-2026-62911) is already publicly accessible. Further emphasizing the widespread exposure, the security watchdog group Shadowserver reported that 21,899 IP addresses with a Microsoft Exchange Server fingerprint are still unpatched and openly accessible online. A significant portion of these vulnerable servers are located in the United States (6,200) and Germany (5,100).

### Broader Context: Persistent Threats to Exchange Environments

This vulnerability is not an isolated incident but rather part of a persistent trend of threats targeting Microsoft Exchange infrastructure. For example, in June, Microsoft patched another Exchange Server vulnerability, [CVE-2026-42897](/cve/cve-2026-42897), which was actively exploited in cross-site scripting ([XSS](/glossary#xss)) attacks impacting Outlook Web Access users. The [Cybersecurity and Infrastructure Security Agency (CISA)](/glossary#cybersecurity-and-infrastructure-security-agency-cisa) added this flaw to its Known Exploited Vulnerabilities Catalog on May 15, mandating U.S. government agencies to patch their servers within two weeks. Since November 2021, CISA has listed 20 Microsoft Exchange Server vulnerabilities in its catalog of actively exploited security issues, with 14 of those also linked to [ransomware](/glossary#ransomware) attacks. This history underscores the critical importance of keeping Exchange servers fully updated and secured.

Furthermore, Microsoft has announced that Exchange 2016 and 2019 reached their end of support, and security updates will cease shipping through the Extended Security Update (ESU) program in October 2026. This end-of-life status for older versions further complicates the security posture for organizations that have not yet migrated, making **patching Microsoft Exchange Server 2016 CVE-2026-62911** and other critical updates even more urgent.

### Actionable Recommendations for Mitigating Exchange Server Authentication Bypass

Given the severity and accessibility of exploit code for [CVE-2026-62911](https://nvd.nist.gov/vuln/detail/CVE-2026-62911), organizations must prioritize remediation efforts. Here are key actions defenders should take:

*   **Immediate Patching:** Apply the August 2026 [Patch Tuesday](/glossary#patch-tuesday) updates to all Microsoft Exchange Server installations without delay. This is the single most effective action to prevent exploitation of CVE-2026-62911.
*   **Address End-of-Life Systems:** For organizations still utilizing Exchange Server 2016 and 2019, which only receive security updates via the [Extended Security Updates (ESU)](/glossary#extended-security-updates-esu) program, NCSC-NL advises ensuring these servers are accessible only internally. Replacing these versions with a supported solution should be a strategic priority. This directly impacts the **mitigating Exchange Server authentication bypass** risks.
*   **Review CISA Known Exploited Vulnerabilities Catalog:** Regularly consult the [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) for critical updates on actively exploited flaws, especially those impacting Microsoft Exchange. Prioritize patching for all listed vulnerabilities.
*   **Harden Exchange Servers:** Implement the joint guidance released by CISA and the National Security Agency (NSA) on [hardening](/glossary#hardening) Exchange servers against attacks. This guidance provides comprehensive recommendations for improving the overall security posture of these critical systems.
*   **[Network Segmentation](/glossary#network-segmentation) and Monitoring:** Implement network segmentation to limit external exposure of Exchange servers. Continuously monitor server logs for any unusual activity, authentication anomalies, or signs of compromise, which could indicate attempts to exploit vulnerabilities like CVE-2026-62911.

**Related:** [CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters](/blog/cve-2024-21319-peoplesoft-auth-bypass-exploited-by-shinyhunters), [CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active](/blog/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-bypass-active)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack
